Privacy
What Cluenta does with your household’s data
Written to be read once and understood, rather than agreed to without reading.
What this page is
Cluenta is in private beta. This page describes how the product handles a household’s data today, so that a household can decide whether to put its receipts in it. A formal privacy policy will accompany general availability and will say who the data controller is and on what legal basis it processes.
What the site collects
Nothing. These marketing pages are static files. They load no third-party script, embed no analytics, set no cookie, and serve their fonts from the same origin, so no request leaves for another company while you read this. The web server keeps ordinary access logs.
What the product holds
The expenses a household records: amount, currency, date, merchant, category, payment method, notes, and who entered or confirmed them. The receipt images sent in through the Telegram flow, stored in object storage and reached through short-lived links rather than public URLs. The household’s members and invitations, its budgets, and an activity trail of the changes made to an expense.
Authentication is handled by a standards-based OIDC identity provider. Cluenta sees the identity it issues, not a password.
What you can do with it
Export it. The owner of a household can request a complete export as JSON or CSV — the data, not a summary.
Pause it. Archiving a household is reversible: a recovery screen can restore it, export it, or delete it permanently.
Delete it. Permanent erasure is asynchronous across the services that hold parts of the household, and the app reports it as still in progress until Account, Expenses, Delivery and Audit have each finished. It does not claim to be done before it is.
Who it is shared with
Everyone in the household sees its ledger and budgets; the actions that cannot be undone casually stay with the owner. Outside the household, data is shared with the infrastructure the environment runs on — hosting, object storage for receipts, database backups and the mail relay that sends invitations — and with nobody else. There is no advertising, no data sale, and no third-party tracker in the product or on this site.
Integrations you control
Machine callers such as n8n authenticate with API keys a household owner issues and can rotate or revoke. Webhook subscriptions are created by the owner, and their delivery history is visible. Anything reaching your data through those paths does so because someone in your household issued the credential.
Questions
Write to hello@cluenta.com. A person answers.